Security 11034 Published by

Today's Linux patch cycle delivered Red Hat's largest batch of 2026 with 44 advisories mostly rated Important, plus SUSE sweeping roughly 206 vulnerabilities driven by a 62-CVE Firefox ESR update. Ubuntu's cycle is dominated by kernel and cloud patches carrying privilege-escalation flaws like the Arm TLB and AMD SEV-SNP issues, while Debian's roundcube and Rails fixes rank among the nastiest on paper. A recurring sudo TZ authentication bypass threads through AlmaLinux, Oracle, and Rocky releases, and Fedora's standout item is a proof-assistant update referencing four Rocq logical-integrity CVEs. With severity tied to CVSS scores across nearly every distro, admins can prioritize kernel, browser, and SSH patches before acting on the lower-risk backports.





Red Hat ships 44 advisories as SUSE chases 62 Firefox holes

Today's Linux security roundup pulls in kernel flaws, forged JWT tokens, and a formal proof assistant that shouldn't verify. Debian, Fedora, Ubuntu, Oracle, and everyone else had their turn.

Red Hat has now delivered its largest errata batch of the 2026 cycle so far. Counting the entries, you are looking at 44 advisories, and the overwhelming majority land at the Important band, which is Red Hat's second-highest severity and usually means something is genuinely exploitable.

Linux Security

Kernel is the package to patch first. Half a dozen kernel updates run across the SAP channel, the EUS long-life add-ons, and standard RHEL, so manage any RHEL hosts and that is where your time goes.

Firefox shows up in a different number of ways, with seven advisories each aimed at a distinct RHEL support track. A standard install will not feel most of them, since SAP Solutions, Telecommunications, and EUS make up the bulk, but take a glance to be sure.

There is one detail here worth a wry smile. Three Red Hat Single Sign-On 7.6.13 updates for RHEL 7, 8, and 9 carry the Important title, yet Red Hat rates their actual security impact as none. You get the full errata machinery for what is basically a maintenance release.

A Firefox problem that outnumbers everything else

If numbers are your measure, SUSE is the week's real heavyweight. The company ran a broad security sweep fixing roughly 206 vulnerabilities across 15 announcements, with two items doing nearly all the heavy lifting.

Firefox leads with 62 fixes riding on Mozilla's 153.4.0 ESR build. That covers sandbox escapes, use-after-frees, and JIT problems packed together. CVE-2026-100788 is the one worth a second look: it scores a 9.8 and needs no user input, so a site you visit could reach into your browser without a single click.

Python is the other giant, with 26 fixes centered on archive handling. The tarfile and zipfile modules and any flavor of decompression ride along with the 3.12.14 release.

The lone Critical tag lands on Tomcat and libtcnative. Java apps serving over AJP or WebSocket pick up 15 fixes, including request smuggling and thread-pinning denial-of-service. Each sounds like a misconfiguration until someone actually ships an exploit.

The rest spreads across the SLE 15 live-patch line, the category of fix you are glad does not demand a reboot. Live Patch 30 shows on both SP5 and SP6, but they touch entirely different kernels, so a shared number means nothing. Keep in mind that while you are cataloging installs.

Kernels and cloud builds

Ubuntu's batch is dominated by kernels.

You get the generic kernel plus cloud-flavored builds for GCP, Azure and its secure CVM variant, Oracle, AWS, IBM, GKE, and OEM and NVIDIA Tegra. Several of these are the same update wearing different cloud hats.

CVE-2022-3114, the i.MX clock driver bug that lets a local attacker crash the box, turns up in a lot of them. The GCP and Oracle kernels also pull in CVE-2025-10263, an Arm TLB issue that actually matters because it can escalate privileges or slip past memory protections.

The newest 26.04 kernels carry CVE-2023-20585, an AMD SEV-SNP flaw that could let a hypervisor-level attacker corrupt encrypted guest memory. Run cloud instances and those are the ones to prioritize.

There is one annoying wrinkle too. Those kernel updates arrive with an ABI change, forcing you to recompile and reinstall any third-party modules you built yourself. Budget time for it if you run DKMS-style setups.

Below the kernels sits the grab bag. Tesseract takes the biggest hit with ten CVEs from crafted OCR model files. libsoup draws eight for HTTP/2 and proxy handling. Then the single-issue crowd: Redis, FreeType, FreeRDP, FluidSynth, Go, libwebsockets, GStreamer, RabbitMQ, Unbound, and Ubuntu Pro for WSL, which was leaking its attach token in command-line arguments, a rather conspicuous slip.

The long tail of distro patches

Debian's round is nastier than its severity badges suggest. The roundcube advisory carries no CVE yet, but bundles a grab bag of webmail trouble: cross-site scripting, a CSRF bypass, email header injection, CSS property injection, and privilege escalation. That is a lot of ways to turn someone else's inbox into someone else's mess.

Rails got the crowded treatment with ten CVEs spanning XSS, denial-of-service, path traversal, and arbitrary code execution. If you run any Rails app and have not updated, this is the longest list you will find today. The bookworm backports also close two puma PROXY protocol headaches and a suricata-update path traversal that lets malformed rules overwrite files on disk.

AlmaLinux spread its updates across releases 8, 9, and 10. The kernels are the big ones by volume, with version 8 taking two near-identical releases, one regular and one real-time, each patching 29 issues, though most are the usual memory-corruption and race-condition bugs across network drivers, KVM, and storage.

The sudo fix deserves a second look. Setting the TZ environment variable let a user slip past time-based authorization, so the NOTBEFORE and NOTAFTER constraints could be bypassed entirely, and it rolled out across all three releases.

That same sudo TZ bypass reappears in the Oracle and Rocky batches this week, and the CVE keeps traveling. The vim patch is worth double-checking as well, since a crafted tags file could trigger arbitrary command execution. Oracle specifically has the gnutls updates that mark ML-KEM as FIPS-unapproved on both OL9 and OL10, which only bites if compliance tooling is poking at your crypto policies.

Fedora leaned into the mundane-but-necessary side of security this week. Fourteen of the Fedora 44 updates cluster around a single advisory, all from a fresh 9.3.0 release of rocq, the formal proof assistant that split off as a maintained fork of Coq. The advisory carries a security flag because it references four Rocq logical-integrity issues, including two 2026 CVEs that let you manufacture proofs that should not verify. Hand Rocq a proof and actually trust the result, and that is the one to watch. Everyone else just got a rebuild.

The standalone fixes are more conventional. httpd jumps to 2.4.69 with six CVEs including a CGI redirect flaw that allows arbitrary code execution. Python 3.14.8 carries seven security fixes, though only one, a use-after-free in SSLContext, gets spelled out. Install those two first if I were you.

Rocky cleared its repos with 26 advisories across releases 8, 9, and 10. Twenty-five sit at Important, with a single Moderate wedged in at ghostscript on release 8. bind, sudo, freerdp, vim, and mariadb-connector-c repeat across releases, and every advisory ties its severity to a specific CVSS score, so you can grade the risk before patching instead of blasting everything at once.

Slackware kept it simple with an openssh update on both 15.0 and -current. The package ships in two flavors per release, each with an MD5 checksum for verification. Simple enough.

A Breakdown of the Updates

AlmaLinux

AlmaLinux pushed a batch of security updates on October 6 across its current and aging releases (versions 8, 9, and 10). Almost every advisory tops out at "Important" severity, and a handful are worth your attention because they open real doors rather than just tidy up housekeeping.

The kernel updates are the big ones by volume. AlmaLinux 8 received two near-identical kernel releases, one regular and one real-time variant, each patching 29 issues. That is a lot of CVE identifiers for a single update, though most of them are the usual memory-corruption and race-condition bugs spread across network drivers, KVM virtualization, and storage paths. If you run either kernel, this lands on your machine.

A few smaller updates deserve a second look. The sudo fix (CVE-2026-96512) covers something quietly useful: setting the TZ environment variable let a user slip past time-based authorization, so the NOTBEFORE and NOTAFTER constraints could be bypassed entirely. It rolled out across all three OS releases. The BIND update for version 10 bundles five denial-of-service holes, mostly around SVCB/HTTPS handling and DNSSEC, while the vim patch (CVE-2026-73073) is the sort that makes you double-check your own config files, since a crafted tags file could trigger arbitrary command execution.

Beyond the headline items sits a grab bag of library fixes. libpcap closed an out-of-bounds read and write that allowed arbitrary memory access, gd patched a GIF buffer overflow, and MariaDB squashed an SQL injection tied to improper big5 character set handling. librabbitmq and GIMP picked up heap overflows, with the image editor absorbing four separate bugs. Node.js gathered two DoS issues, and Ruby 2.5 saw its DNS resolver and MongoDB driver patched.

Advisory IDPackageVersionSeverityCVEs
ALSA-2026:75746kernel-rt8Important29
ALSA-2026:75747kernel8Important29
ALSA-2026:75680gd8Important1
ALSA-2026:75674mariadb-connector-c8Important1
ALSA-2026:75580sudo8Important1
ALSA-2026:75582librabbitmq8Important1
ALSA-2026:76045libpcap8Important1
ALSA-2026:73519ruby:2.58Important2
ALSA-2026:75673mariadb-connector-c9Important1
ALSA-2026:75571sudo9Important1
ALSA-2026:75575gimp9Important4
ALSA-2026:74438kernel9Moderate3
ALSA-2026:75579sudo10Important1
ALSA-2026:75769vim10Important1
ALSA-2026:75577bind10Important5
ALSA-2026:75864nodejs2210Important2
ALSA-2026:75581mod_auth_openidc10Important1

Debian GNU/Linux

Debian shipped a batch of security patches this week, and a few of them deserve your attention before something less pleasant does. Most of the fixes land in trixie (the current stable release), while two are LTS backports for the older bookworm.

The roundcube advisory is the nastiest on paper: no CVE number yet, but a grab bag of webmail trouble including cross-site scripting, a CSRF bypass, email header injection, CSS property injection, and privilege escalation. That's a lot of ways to turn someone else's inbox into someone else's mess. It's patched in 1.6.19+dfsg-0+deb13u1.

Rails got the crowded treatment, with ten CVEs spanning XSS, denial-of-service, path traversal, and arbitrary code execution. If you run any Rails app and haven't updated, this is the longest list here. ruby-jwt missed on HMAC validation for some tokens, which is the exact gap that makes a forged token look legitimate, and node-shell-quote closes a denial-of-service and a shell injection hole. All three trixie fixes are already out.

On the LTS side, puma has two PROXY protocol headaches: one lets an attacker keep sending bytes without CRLF to pin down memory and CPU, and the other lets someone spoof the source IP by replaying a PROXY header over a kept-alive connection. suricata-update takes a path traversal that lets malformed rules overwrite files on disk. Both backports are for bookworm.

Upgrading through your normal update path covers all of it.

PackageCVE(s)What it doesFixed inBranch
roundcubenone assigned yetXSS, CSRF bypass, header injection, CSS injection, remote content bypass, info disclosure, privilege escalation1.6.19+dfsg-0+deb13u1trixie (stable)
railsCVE-2026-33168, 33169, 33170, 33173, 33174, 33176, 33195, 33202, 33658, 66066XSS, DoS, path traversal, arbitrary code execution2:7.2.2.2+dfsg-2~deb13u2trixie (stable)
node-shell-quoteCVE-2026-13311, CVE-2026-102422Denial-of-service, shell command injection1.7.4+~1.7.1-1+deb13u2trixie (stable)
ruby-jwtCVE-2026-45363Insufficient HMAC validation lets forged tokens through2.7.1-1+deb13u1trixie (stable)
pumaCVE-2026-47736, CVE-2026-47737Memory/CPU exhaustion and source IP spoofing via PROXY protocol v15.6.5-3+deb12u2bookworm (LTS)
suricata-updateCVE-2026-63347Path traversal lets malformed rules overwrite files1.2.7-1+deb12u1bookworm (LTS)

Fedora Linux

Fedora's push this week leans hard into the mundane-but-necessary side of security updates rather than any headline CVE. Fedora 44 picked up a wide pile of packages, with a few items following along on 43.

Fourteen of the Fedora 44 updates cluster around a single advisory, all kicked off by the same root cause: a fresh 9.3.0 release of rocq, the formal proof assistant that split off as a maintained fork of Coq. Why3, zenon, flocq, and gappalib-coq were simply rebuilt against it, while rocq itself and its standard library got the actual version bumps. The advisory is flagged security because it references four Rocq logical-integrity issues, including two CVEs from 2026 that let you manufacture proofs that should not verify. If you ever hand Rocq a proof and actually trust the result, that's the one worth paying attention to; everyone else just gets a rebuild.

The standalone security patches are more conventional. httpd jumps to 2.4.69 and bundles six distinct CVEs spanning use-after-free bugs in mod_ldap and mod_http2, a denial of service in mod_proxy_ftp, a CGI redirect flaw that allows arbitrary code execution, a shared-lock DoS, and session cookie leakage during internal redirects. Python 3.14.8 carries seven security fixes, though only one (a use-after-free in SSLContext) gets spelled out in the tracker. Those two are the ones I'd install first if I were you.

Below those, the rest are mostly single-issue hardening. tesseract and libical each absorb backported buffer-overflow and DoS fixes, cockpit caps concurrent connections and sanitizes URLs, musescore patches a FluidSynth heap overflow triggered by a MIDI setting, janus lands a security release that quietly fixes memory leaks and a couple of plugin bypasses, and golang-x-mod gets rebuilt to absorb a batch of Go standard-library holes. Freerdp and the accompanying python3-docs round out the batch without touching a vulnerability.

Three of these (janus, golang-x-mod, tesseract) also shipped for Fedora 43, since 43 is in maintenance mode and takes only security backports rather than fresh feature versions.

PackageFedoraVersionWhat changedThe catch
why3441.8.2-11Rebuilt for rocq 9.3.0Pure rebuild; advisory flags four Rocq logical-integrity CVEs
rocq-stdlib449.2.0-1Up to 9.2.0, now uses dune buildsystemStandard library for the Rocq prover
zenon440.8.5-41Rebuilt for rocq 9.3.0Automated theorem prover, rebuild only
rocq449.3.0-1Up to 9.3.0, fix rocq.xmlCore prover; advisory covers 4 CVEs
gappalib-coq441.11.0-1Up to 1.11.0, rocq 9.3.0 compat patchCoq support for the Gappa prover
flocq444.2.2-3Rebuilt for rocq 9.3.0Float formalization, rebuild only
httpd442.4.69-1Up to 2.4.696 CVEs (2 after-free, DoS x3, CGI RCE, cookie leak)
python3.14443.14.8-1Up to 3.14.87 security fixes (SSLContext UAF only one detailed)
python3-docs443.14.8-1Docs for 3.14.8Companion docs, no vuln fix
freerdp443.32.1-1Up to 3.32.1Bugfix release, no vuln fix
janus441.4.2-1Up to 1.4.2 security releaseMemory leaks, plugin bypasses, thread caps
musescore444.7.5-3Patch CVE-2026-61714FluidSynth heap overflow via MIDI config
golang-x-mod440.28.0-5Rebuilt for security fixes4 Go stdlib CVEs (tls, pem, asn1, x509)
libical443.0.20-8Patch CVE-2026-88383DoS via crafted iCalendar property
cockpit44368-1Limit connections, sanitize URLs3 CVEs (DoS, trailing slash, PackageKit)
tesseract445.5.3-2Backport CVE-2026-88047 to 880548 buffer-overflow fixes
janus431.4.2-1Security releaseSame hardening as F44
golang-x-mod430.27.0-4Rebuilt for security fixesSame Go stdlib CVEs (0.27.0 build)
tesseract435.5.3-2Backport CVE-2026-88047 to 88054Same 8 overflow fixes

Oracle Linux

Oracle Linux has pushed another round of errata, and this batch stretches from the aging OL7 all the way up to the relatively new OL10. It's a grab bag of "Important" security advisories mixed with ordinary bug-fix-and-enhancement updates, so you get to pick whichever applies to your stack.

Two security rollups carry the most baggage. The vim update for OL9 and the kernel update for OL8 each bring a long tail of CVEs, the latter running to nearly three dozen. A handful of vulnerabilities show up more than once: the sudo TZ environment variable authentication bypass (CVE-2026-96512) landed on OL8, OL9, and OL10, while mariadb-connector-c's flaw (CVE-2026-44172) got patched on both OL8 and OL9.

The gnutls updates are about as nerve-wracking as it gets. Both the OL9 and OL10 releases just mark ML-KEM as FIPS-unapproved. Nothing to panic about unless you have compliance tooling poking at crypto policies. The nodejs22 advisory for OL10 is another bit of a puzzle, it names two CVEs but the only change listed is adding c-ares as a dependency, which suggests the real fix arrived in an earlier bump.

On the bug-fix side, a few of these are quietly useful. The OL7 iscsi-initiator-utils patch repairs a hypervisor that wouldn't boot over iSCSI due to truncation, which is exactly the sort of problem that ruins your weekend. The oVirt vdsm updates run the same VM-cloning fix on OL8 and OL9, and the ovirt-engine refresh just re-reads storage-pool metadata after a master-role switch.

AdvisoryOSPackageTypeWhat it actually does
ELBA-2026-500369OL8vdsm (36 packages)Bug fixFixes VM cloning problem on OL9
ELBA-2026-500368OL8ovirt-engine-applianceBug fixAdds an OL9 appliance (release note is delightfully garbled)
ELBA-2026-500366OL8ovirt-engineBug fixRefreshes storage-pool metadata on every UP host after a master-role switch
ELSA-2026-75673OL9mariadb-connector-cSecurityCVE-2026-44172 fix
ELSA-2026-75768OL9vimSecurityCVEs for command injection, buffer overflows, and code execution across omni-completion, netrw, terminal emulator, and more
ELSA-2026-75571OL9sudoSecurityCVE-2026-96512 (TZ env var bypasses NOTBEFORE/NOTAFTER auth)
ELBA-2026-76028OL9gnutlsBug fix/enhancementMarks ML-KEM FIPS-unapproved
ELBA-2026-500371OL9keepalivedBug fixStops restoring file timestamps while inspecting scripts
ELSA-2026-76045OL8libpcapSecurityCVE-2026-0799, adding bounds checks for BPF scratch memory register indices
ELSA-2026-75747OL8kernelSecurity/Bug/enhancement28 CVEs plus driver signing and certificate updates
ELSA-2026-75580OL8sudoSecurityCVE-2026-96512 plus a long backlist of prior sudo fixes
ELSA-2026-75674OL8mariadb-connector-cSecurityCVE-2026-44172 fix
ELBA-2026-500365OL7iscsi-initiator-utilsBug fixFixes hypervisor failing to boot over iSCSI due to truncation
ELSA-2026-75864OL10nodejs22SecurityCVE-2026-9496 and CVE-2026-19534 (only real change: adds c-ares dependency)
ELSA-2026-75579OL10sudoSecurityCVE-2026-96512 plus execveat and privilege-drop fixes
ELBA-2026-76027OL10gnutlsBug fix/enhancementMarks ML-KEM FIPS-unapproved
ELBA-2026-500370OL9vdsm (36 packages)Bug fixFixes VM cloning problem
ELBA-2026-500367OL9ovirt-engineBug fixRefreshes storage-pool metadata after a master-role switch
ELSA-2026-75570OL10freerdpSecurity11 CVEs backported across Remote Desktop handling

Red Hat Enterprise Linux

Red Hat has pushed another round of security errata, and the 2026 batch is a sizable one. Counting the list, you are looking at 44 advisories, and the vast majority land at the Important rating. That is Red Hat's second-highest band, which usually means there is something exploitable worth patching.

Firefox turns up more often than anything else, with seven separate advisories each aimed at a different RHEL channel or support track. If you run a standard RHEL install, most of these specialty variants (SAP Solutions, Telecommunications, EUS) will not touch you, but it is worth a glance to confirm.

Kernel is the other heavy hitter. Half a dozen kernel updates span everything from the SAP channel to the long-life EUS add-ons. If you manage RHEL hosts, kernel is the package to patch first.

Two things stand out in the pile. First, three Red Hat Single Sign-On 7.6.13 updates for RHEL 7, 8, and 9 carry the Important title while Red Hat rates their actual security impact as none. You get the full errata machinery for what amounts to a maintenance release. Second, the only three Moderate advisories this round are firewalld, glibc, and ghostscript, the kind of lower-risk fixes you can slot into the next routine window rather than the next maintenance action.

OpenShift gets its share as well. Releases 4.22.17, 4.21.36, 4.20.41, and 4.19.50 arrive alongside a MicroShift 4.21.36. If you orchestrate containers on RHEL, that cluster-wide work is where your attention should go.

RHSA IDProductSeverityRHEL Channel / Notes
RHSA-2026:76637Apicurio Registry (container images) 3.3.3 GAImportantContainer Catalog
RHSA-2026:75768vimImportantRHEL 9
RHSA-2026:76733rust-rpm-sequoiaImportantRHEL 9
RHSA-2026:76734rust-rpm-sequoiaImportantRHEL 10
RHSA-2026:76735rust-sequoia-sqvImportantRHEL 10
RHSA-2026:76740firefoxImportantRHEL 9.4 SAP Solutions
RHSA-2026:76741firefoxImportantRHEL 7 Extended Lifecycle Support
RHSA-2026:76742firefoxImportantRHEL 9.2 SAP Solutions
RHSA-2026:76743opentelemetry-collectorImportantRHEL 10
RHSA-2026:76745firefoxImportantRHEL 8.6 AMCUSS + EUS Long-Life
RHSA-2026:76746firefoxImportantRHEL 8.8 SAP + Telecommunications
RHSA-2026:76747freerdpImportantRHEL 8
RHSA-2026:76748opensshImportantRHEL 10.0 EUS
RHSA-2026:76762perl-DBIImportantRHEL 10
RHSA-2026:76763dovecotImportantRHEL 8
RHSA-2026:76777glibcModerateRHEL 8
RHSA-2026:76795grafanaImportantRHEL 9.4 SAP Solutions
RHSA-2026:76809grafanaImportantRHEL 9.2 SAP Solutions
RHSA-2026:76844firewalldModerateRHEL 9.6 EUS
RHSA-2026:76877ghostscriptModerateRHEL 8
RHSA-2026:76894firefoxImportantRHEL 8.4 AMCUSS + EUS Long-Life
RHSA-2026:76895firefoxImportantRHEL 9.6 EUS
RHSA-2026:76945python3.9ImportantRHEL 9.2 SAP Solutions
RHSA-2026:76993opensshImportantRHEL 9.4 SAP Solutions
RHSA-2026:77028python3.12ImportantRHEL 8
RHSA-2026:77214kernel-rtImportantRHEL 9.2 SAP Solutions
RHSA-2026:77215kernelImportantRHEL 9.2 SAP Solutions
RHSA-2026:77216kernelImportantRHEL 8.6 AMCUSS + EUS Long-Life
RHSA-2026:77217kernelImportantRHEL 8.4 AMCUSS + EUS Long-Life
RHSA-2026:77218kernelImportantRHEL 9.4 SAP Solutions
RHSA-2026:77301kernelImportantRHEL 8.8 SAP + Telecommunications
RHSA-2026:77370mod_auth_openidc:2.3ImportantRHEL 8.8 SAP + Telecommunications
RHSA-2026:77371mod_auth_openidc:2.3ImportantRHEL 8.6 AMCUSS + EUS
RHSA-2026:77372mod_auth_openidc:2.3ImportantRHEL 8.4 AMCUSS + EUS Long-Life
RHSA-2026:74376OpenShift Container Platform 4.20.41ImportantOpenShift
RHSA-2026:74377OpenShift Container Platform 4.20.41ImportantOpenShift
RHSA-2026:74379OpenShift Container Platform 4.21.36ImportantOpenShift
RHSA-2026:74427OpenShift Container Platform 4.22.17ImportantOpenShift
RHSA-2026:74428OpenShift Container Platform 4.22.17ImportantOpenShift
RHSA-2026:74433OpenShift Container Platform 4.19.50ImportantOpenShift
RHSA-2026:74796MicroShift 4.21.36ImportantOpenShift (MicroShift)
RHSA-2026:76128Red Hat Single Sign-On 7.6.13NoneRHEL 7
RHSA-2026:76129Red Hat Single Sign-On 7.6.13NoneRHEL 8
RHSA-2026:76130Red Hat Single Sign-On 7.6.13NoneRHEL 9

Rocky Linux

Rocky Linux just cleared out its repos with a batch of errata, and the gist is that you've got a pile of security updates sitting there. Across three releases (8, 9, and 10), that's 26 advisories, 25 flagged Important and one wedged at Moderate.

The kernel updates are usually the ones that draw the most attention, and they're spread the way you'd expect. Rocky Linux 8 got both a regular kernel and a real-time build, while the newer 10.0 picked up a fresh kernel too. If your 8 boxes run real-time workloads, kernel-rt is the one to grab.

bind, sudo, freerdp, vim, and mariadb-connector-c are the repeat offenders, showing up in two or three releases each. Not exactly a shocker, given how often those packages turn up in vulnerability reports. The rest are mostly single calls: gd, librabbitmq, libvirt, mod_auth_openidc, nodejs (both the module stream on 8 and the 10.0 package), libpcap, dovecot, and rust-rpm-sequoia. The pki-core:10.6 update on 8 drags along a whole cluster of related modules, so that one covers more ground than the name suggests.

The only Moderate severity is ghostscript on release 8, which means it can wait behind the Important entries if you're triaging. Every advisory ties its severity to a specific CVSS base score tied to individual CVEs, so you can grade the risk before you patch rather than just applying everything at once.

RLSA IDPackage(s)ReleaseSeverity
RSA-2026:75767bindLinux 9Important
RSA-2026:75571sudoLinux 9Important
RSA-2026:75578bind9.18Linux 9Important
RSA-2026:75673mariadb-connector-cLinux 9Important
RSA-2026:76733rust-rpm-sequoiaLinux 9Important
RSA-2026:75768vimLinux 9Important
RSA-2026:75746kernel-rtLinux 8Important
RSA-2026:75674mariadb-connector-cLinux 8Important
RSA-2026:75680gdLinux 8Important
RSA-2026:75582librabbitmqLinux 8Important
RSA-2026:75747kernelLinux 8Important
RSA-2026:75580sudoLinux 8Important
RSA-2026:75870nodejs:22Linux 8Important
RSA-2026:75573pki-core:10.6 (tomcatjss, resteasy, ldapjdk, jss, plus module variants)Linux 8Important
RSA-2026:76763dovecotLinux 8Important
RSA-2026:76877ghostscriptLinux 8Moderate
RSA-2026:76747freerdpLinux 8Important
RSA-2026:76045libpcapLinux 8Important
RSA-2026:75570freerdpLinux 10Important
RSA-2026:75577bindLinux 10Important
RSA-2026:75583libvirtLinux 10Important
RSA-2026:75769vimLinux 10Important
RSA-2026:75581mod_auth_openidcLinux 10Important
RSA-2026:75579sudoLinux 10Important
RSA-2026:75576kernelLinux 10Important
RSA-2026:75864nodejs22Linux 10Important

Slackware Linux

Slackware pushed an openssh update out this time around, and it's the kind of security patch you want to apply without much fuss. openssh 10.6p1 (advisory SSA:2026-279-01) lands on both Slackware 15.0 and -current to close out some security holes. SSH is about as important as any service you're running, so this one earns the priority rather than sitting at the bottom of a queue.

The packages come in two flavors per release. Slackware 15.0 gets i586 and x86_64 builds, while -current ships i686 and x86_64 (the newer baseline, as you'd expect). Each has an MD5 checksum so you can verify the download before installing. The upgrade path is the usual Slackware dance: run upgradepkg as root against the matching .txz, then restart sshd with the rc script. It's a small update, but it's the thing you're relying on to keep the doors to your boxes open.

VersionAdvisoryMD5 (i386)MD5 (x86_64)Action
openssh-10.6p1SSA:2026-279-015b260bc4e7cebdc5cc4f6baf8d01e2b8 (15.0) / ccd016b5c4c2be7bad2637a5bc9c6386 (-current)00207779419c3a4a10b95e900dd226b6 (15.0) / ede230efe189fda322fd4da20bef7ae0 (-current)upgradepkg, then restart sshd

SUSE Linux

SUSE put out a sizeable security sweep, and the short version is: if any of the 15 versions below are on your systems, schedule some patching. The day's two biggest items landed in Firefox and Python, 62 and 26 fixed vulnerabilities respectively, out of roughly 206 across the whole batch. The rest is Linux kernel live patches, which is the category of fix you're glad doesn't need a reboot.

Firefox is the one that genuinely wants your attention. Mozilla's 153.4.0 ESR build closes a broad set of holes, several sandbox escapes, use-after-frees, and JIT problems thrown together. CVE-2026-100788 deserves a look on its own merits: it's a 9.8 and takes no user input, meaning a site you visit could reach you without a single click.

Python 3.12's haul centers on archive handling, tarfile, zipfile, decompression of any kind. The update rides along with the 3.12.14 release, so security and routine bug fixes arrive together.

The kernel patches spread across SLE 15 SP4 through SP7, with SP4 ending up with three of them (57, 58, plus the earlier 30). SP5 and SP6 both carry a "Live Patch 30," but they patch entirely different kernels, so the shared number means nothing. Everything reads "important" on SUSE's scale, just below critical.

The only critical tag goes to the Tomcat and libtcnative bundle. Java apps serving over AJP or WebSocket get 15 fixes here, covering request smuggling and thread-pinning denial of service. Both sound like misconfiguration until someone shows you the exploit.

The remainder of the Tumbleweed announcements are smaller fry: valkey, a few Python packages, and jupyterlab. Most carry a single CVE, though Werkzeug picked up six. Chromium closed 11 holes for openSUSE Backports on SP7.

AnnouncementWhat it updatesCVEs fixedSeverityNotes
SUSE-SU-2026:4545-1MozillaFirefox62ImportantFirefox ESR 153.4.0
SUSE-SU-2026:4534-1python31226ImportantRides 3.12.14
SUSE-SU-2026:4518-1Linux kernel (Live Patch 4)19ImportantSLE 15 SP6 + SP7, kernel 6.4
SUSE-SU-2026:4544-1libtcnative-1-0 / tomcat1115CriticalTomcat 11.0.26, libtcnative 1.3.9
SUSE-SU-2026:4519-1Linux kernel (Live Patch 33)13ImportantSLE 15 SP4 + SP5, kernel 5.14
SUSE-SU-2026:4516-1Linux kernel (Live Patch 30)13ImportantSLE 15 SP5, kernel 5.14
SUSE-SU-2026:4530-1Linux kernel (Live Patch 57)12ImportantSLE 15 SP4, kernel 5.14
SUSE-SU-2026:4540-1Linux kernel (Live Patch 30)11ImportantSLE 15 SP6, kernel 6.4
openSUSE-SU-2026:0345-1chromium11ImportantChromium 154.0.8037.97, Backports SP7
SUSE-SU-2026:4531-1Linux kernel (Live Patch 58)7ImportantSLE 15 SP4, kernel 5.14
openSUSE-SU-2026:11943-1python313-Werkzeug6Moderate6 CVEs
openSUSE-SU-2026:11949-1python3104Moderate3.10.21, Tumbleweed
openSUSE-SU-2026:11945-1jupyter-jupyterlab3Moderate4.5.11, Tumbleweed
openSUSE-SU-2026:11951-1valkey1Moderate9.1.2, Tumbleweed
openSUSE-SU-2026:11946-1python313-langchain-anthropic1Moderate1.7.5, Tumbleweed
openSUSE-SU-2026:11944-1python313-azure-storage-queue1Moderate12.18.0, Tumbleweed
openSUSE-SU-2026:11947-1python313-sglang1Moderate0.5.20, Tumbleweed

Ubuntu Linux

Ubuntu rolled out another batch of security patches. This roundup is a mixed lot. The kernel updates carry the most substance, while the application fixes range from the mildly annoying to the genuinely worth a reboot.

The kernels eat up most of the space. You get the generic kernel plus cloud-flavored builds for GCP, Azure (and its secure CVM variant), Oracle, AWS, IBM, GKE, along with OEM and NVIDIA Tegra. Several of these are the same update wearing different cloud hats, and a couple of notices stack multiple CVEs. CVE-2022-3114, the i.MX clock driver bug that lets a local attacker crash the machine, shows up in a lot of them. GCP and Oracle kernels also pull in CVE-2025-10263, an Arm TLB issue that is actually worth your time because it can escalate privileges or slip past memory protections. The newer 26.04 kernels carry CVE-2023-20585, an AMD SEV-SNP flaw that could let a hypervisor-level attacker corrupt encrypted guest memory. If you run cloud instances, those are the ones to prioritize. And watch out for the ABI change attached to the kernel updates, since it forces you to recompile and reinstall any third-party modules you built yourself.

The application fixes are the grab bag below. Tesseract takes the biggest hit with ten CVEs, mostly about crafted OCR model files leading to code execution. libsoup pulls in eight, mostly HTTP/2 and proxy handling. U-Boot picks up four for its ZFS, ext4, and IP defragmentation handling. Then there's the single-issue crowd: sg3-utils running commands as root, Redis, FreeType, FreeRDP, FluidSynth, Go, libwebsockets, GStreamer, RabbitMQ, Unbound, and Ubuntu Pro for WSL, which was leaking its attach token in command-line arguments, a rather conspicuous mistake. A few notices, like FreeRDP and the NVIDIA Tegra kernel, don't list a CVE at all.

USNSoftwareVulnerabilityCVE(s)Affected releasesAction
USN-8873-1UnboundMemory mishandling, DoS or code executionCVE-2026-81642, CVE-2026-827177 LTS releases (14.04 through 26.04)Update unbound, libunbound8, python3-unbound
USN-8878-1linux-gcp-5.15 (GCP kernel)i.MX clock null deref; Arm TLB priv-escCVE-2022-3114, CVE-2025-10263Ubuntu 20.04 LTSUpdate linux-image-gcp-5.15; reboot
USN-8877-1linux-gcp / linux-gcp-fips (5.15)i.MX clock null derefCVE-2022-3114Ubuntu 22.04 LTSUpdate; reboot
USN-8876-1linux-azure-fde (Azure CVM kernel)i.MX clock null derefCVE-2022-3114Ubuntu 22.04 LTSUpdate; reboot
USN-8879-1linux-oracle-5.15i.MX clock null deref; Arm TLB priv-escCVE-2022-3114, CVE-2025-10263Ubuntu 20.04 LTSUpdate; reboot
USN-8875-1linux (generic + many cloud variants)i.MX clock null deref (plus broad kernel fixes)CVE-2022-3114Ubuntu 22.04, 20.04 LTSUpdate; reboot
USN-8869-1RabbitMQ ServerHTTP/2 header handling exhausts memoryCVE-2026-592484 LTS releases (20.04 through 26.04)Update; restart RabbitMQ
USN-8881-1FreeTypeCID font loader leads to DoSCVE-2026-955123 LTS releases (22.04 through 26.04)Update libfreetype6
USN-8880-1FreeRDP (freerdp3)Multiple issues: info leak, crash, code execution(no CVE listed)Ubuntu 26.04, 24.04 LTSUpdate freerdp3
USN-8874-1sg3-utilsImproper device ID sanitizing runs commands as adminCVE-2026-163137 LTS releases (14.04 through 26.04)Update sg3-utils
USN-8882-1Tesseract10 CVEs from crafted .traineddata files; DoS or code executionCVE-2026-73066 through CVE-2026-880547 LTS releases (14.04 through 26.04)Update libtesseract*
USN-8887-1linux (7.0 + cloud variants)AMD SEV-SNP RMP check flaw (encrypted guest memory)CVE-2023-20585Ubuntu 26.04 LTSUpdate; reboot
USN-8886-1linux-nvidia-tegra (5.15)Multiple kernel issues(no CVE listed)Ubuntu 24.04 LTSUpdate; reboot
USN-8889-1linux-oem-7.0AMD SEV-SNP RMP check flawCVE-2023-20585Ubuntu 26.04 LTSUpdate; reboot
USN-8888-1linux-azure / linux-azure-fde (7.0)AMD SEV-SNP RMP check flawCVE-2023-20585Ubuntu 26.04 LTSUpdate; reboot
USN-8885-1FluidSynthpitch_bend_range + MIDI channel heap overflowCVE-2026-58264, CVE-2026-617147 LTS releases (14.04 through 26.04)Update fluidsynth
USN-8883-1Go (golang-1.18/1.21/1.24)idna Punycode handling bypasses hostname access controlsCVE-2026-39821Ubuntu 22.04 LTSUpdate golang
USN-8884-1U-BootZFS/ext4/IP defrag handling, code exec or DoSCVE-2025-70290, CVE-2025-70293, CVE-2026-15390, CVE-2026-719716 LTS releases (16.04 through 26.04)Update u-boot-tools
USN-8892-1wsl-pro-service (Ubuntu Pro for WSL)Attach token exposed in command-line argumentsCVE-2026-1023714 LTS releases (20.04 through 26.04)Update wsl-pro-service
USN-8890-1libsoup2.4 / libsoup38 CVEs: HTTP/2, proxy auth, Range headers, chunked parsingCVE-2026-4271, CVE-2026-5119, CVE-2026-6324, CVE-2026-66339, CVE-2026-77014, CVE-2026-77680, CVE-2026-85197, CVE-2026-855346 LTS releases (16.04 through 26.04)Update libsoup
USN-8893-1libwebsocketsHTTP/2 HPACK + CBOR/LECP buffer overflows, code execCVE-2026-19773, CVE-2026-781616 LTS releases (16.04 through 26.04)Update libwebsockets
USN-8866-1RedisTLS pending-data memory management; cluster bus packetsCVE-2026-81934, CVE-2026-929253 LTS releases (22.04 through 26.04)Update redis
USN-8863-1GStreamer Good PluginsFLAC, AVI, closed caption parsing, info disclosure or DoSCVE-2026-17072, CVE-2026-73433, CVE-2026-73434, CVE-2026-889146 LTS releases (16.04 through 26.04)Update gstreamer1.0-plugins-good

How to apply these Linux security updates

Before running any update commands, check which services are currently active on your system. If Nginx or Apache is handling live traffic, schedule a brief maintenance window or use rolling restarts to minimize downtime during the patching process. Desktop users can usually apply these fixes by opening a terminal and running the standard package manager command for their distribution followed by an upgrade flag. A reboot will be necessary if the kernel received updates to ensure the new security modules load correctly.

Power users who rely on command-line tools like jq should verify the patch level after installation. Regression bugs can occasionally break scripts that depend on specific JSON parsing behavior, so a quick test run is worth the few minutes it takes. If you use PackageKit or other GUI package managers and prefer to skip them because they sometimes hang or try to install junk, do not let that stop you from running the command-line equivalent to get these critical patches applied.

Applying these patches requires distribution-specific package management commands. RHEL-based systems typically use dnf update or yum update, while Debian and Ubuntu rely on apt upgrade. SUSE users should run zypper patch to properly address all security advisories, and Slackware administrators can manage updates with upgradepkg or slackpkg. After executing the commands, a reboot is usually necessary for kernel changes to take effect. Finally, review your package manager’s logs to verify that all patches installed successfully and no dependencies were disrupted.

Debian/Ubuntu (apt)

The first thing to do is refresh the local package index; running sudo apt update contacts all configured repositories and pulls in the newest lists of available versions. Skipping this step leaves the system blind to any recent uploads, which explains why “upgrade” sometimes claims there’s nothing to do even after a security advisory has been published. Once the index is current, invoke sudo apt upgrade -y; the -y flag answers every prompt automatically so the process doesn’t pause for user input. This command upgrades all installed packages that have newer versions in the repositories while preserving configuration files.

sudo apt update
sudo apt upgrade -y

Fedora/RedHat/Rocky/Alma/Oracle (dnf or yum)

On modern Fedora and recent Red Hat derivatives, dnf is the package manager; older RHEL releases still rely on yum. Begin with a check‑update operation—sudo dnf check-update or sudo yum check-update—to see exactly which packages are awaiting an upgrade. This preview step can be useful for spotting unexpected kernel bumps before they land. To actually apply the updates, run sudo dnf upgrade -y (or sudo yum update if you prefer the older tool). The upgrade command pulls down the new binaries and runs any necessary post‑install scripts, such as rebuilding initramfs when a kernel changes.

sudo dnf check-update
sudo dnf upgrade -y

or on older releases

sudo yum check-update
sudo yum update

SUSE (zypper)

SUSE’s command line front‑end is called zypper. First execute sudo zypper refresh so that the metadata for all enabled repos gets updated; without this, zypper will happily report “No updates available” even though newer packages sit on the mirror. After a fresh refresh, issue sudo zypper update -y; this upgrades every package to the latest version in the configured repositories and automatically handles service restarts when required.

sudo zypper refresh
sudo zypper update -y

Slackware (slackpkg and pkgtool)

Slackware doesn’t have a single unified updater, but the official way to pull updates is through slackpkg. Start with sudo slackpkg update to download the newest package list from the chosen mirror. Then run sudo slackpkg upgrade-all; this command walks through each installed package and replaces it with the most recent build available in the official repository. For users who prefer a more granular approach, specifying a package name after upgrade limits the operation to that single item. When dealing with community‑maintained repositories, pkgtool takes over: a combined sudo pkgtool update && sudo pkgtool upgrade will sync and apply updates from the mirrors listed in /etc/slackpkg/mirrors.

sudo slackpkg update
sudo slackpkg upgrade-all